CVE-2026-2942: ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSolfileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProSolution WP Clientto a version that resolves this vulnerability.Fixed in 1.9.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2942?
CVE-2026-2942 is classified as a critical severity vulnerability due to its potential for unauthenticated arbitrary file uploads.
How do I fix CVE-2026-2942?
To fix CVE-2026-2942, update the ProSolution WP Client plugin to version 1.9.10 or later.
What is affected by CVE-2026-2942?
CVE-2026-2942 affects the ProSolution WP Client plugin for WordPress versions up to and including 1.9.9.
What type of vulnerability is CVE-2026-2942?
CVE-2026-2942 is an unauthenticated arbitrary file upload vulnerability.
Are there any exploit mitigations for CVE-2026-2942?
Mitigations for CVE-2026-2942 include ensuring proper file type validation and disabling the affected upload functionality until patched.